First published: Tue Aug 10 2021(Updated: )
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE Trojita | =0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38372 is a vulnerability in KDE Trojita 0.7 where man-in-the-middle attackers can create new folders due to untagged responses from an IMAP server being accepted before STARTTLS.
CVE-2021-38372 has a severity rating of 3.7, which is considered medium.
CVE-2021-38372 affects KDE Trojita 0.7, allowing man-in-the-middle attackers to create new folders.
The CWE ID for CVE-2021-38372 is CWE-77.
Yes, the following references provide more information on CVE-2021-38372: [Link 1](https://bugs.kde.org/show_bug.cgi?id=432353), [Link 2](https://nostarttls.secvuln.info).